Hey,
This is my first time playing with an SRX, and I'm a little stuck. Setup:
fe-0/0/0 <--> ISP
fe-0/0/1 <--> Server
We have a publically addressed /27 we want to use internally. We want the SRX to be in ethernet-switch mode, however also respond on both loopback (lo0) and a vlan interface (vlan.0). As it stands right now, we can ping the server connected to the SRX, but we cannot hit the SRX. Our mac address table is populated correctly, as is our ARP table.
- From the Server, ISP gateway responds to ICMP.
- From the SRX, ISP gateway does not respond to ICMP.
- From the Server, SRX responds to ICMP, TCP
- From outside, Server responds to ICMP
- From outside, SRX responds to ICMP (as per tcpdump), but packet never reaches destination.
Looking at the outputs from tcpdump, I can see from the RE, we're sending the reply, however that return packet never reaches the source. I suspect that there's still some firewall-y weirdness happening, however since I'm not a firewall guy, I cannot find where.
Configuration:
> show configuration | display set
set version 11.2R4.3
set system services ssh root-login allow
set system services ssh protocol-version v2
set system syslog archive size 100k
set system syslog archive files 3
set system syslog user * any emergency
set system syslog file messages any info
set system syslog file messages authorization info
set system syslog file interactive-commands interactive-commands error
set system max-configurations-on-flash 20
set system max-configuration-rollbacks 20
set system license autoupdate url https://ae1.juniper.net/junos/key_retrieval
set interfaces fe-0/0/0 unit 0 family ethernet-switching vlan members default
set interfaces fe-0/0/1 unit 0 family ethernet-switching vlan members default
set interfaces fe-0/0/2 unit 0 family ethernet-switching vlan members default
set interfaces fe-0/0/3 unit 0 family ethernet-switching vlan members default
set interfaces fe-0/0/4 unit 0 family ethernet-switching vlan members default
set interfaces fe-0/0/5 unit 0 family ethernet-switching vlan members default
set interfaces fe-0/0/6 unit 0 family ethernet-switching vlan members default
set interfaces fe-0/0/7 unit 0 family ethernet-switching vlan members default
set interfaces lo0 unit 0 family inet address XXX.XXX.XXX.XXX/27
set interfaces vlan unit 0 family inet address XXX.XXX.XXX.XXX/27
set routing-options static route 0.0.0.0/0 next-hop XXX.XXX.XXX.XXX
set security policies default-policy permit-all
set security zones security-zone z1 host-inbound-traffic system-services all
set security zones security-zone z1 host-inbound-traffic protocols all
set security zones security-zone z1 interfaces all
set vlans default vlan-id 1
set vlans default l3-interface vlan.0
If anyone could shed some light on this, that would be very helpful.